FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-6635

This CVE name corresponds to:

Entered Topic
2013-12-05 chromium -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-6635
Phase Assigned(20131105)

Description

Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that triggers removal of a node during processing of the DOM tree, related to CompositeEditCommand.cpp and ReplaceSelectionCommand.cpp.

References

Source Reference
CONFIRM http://googlechromereleases.blogspot.com/2013/12/stable-channel-update.html
CONFIRM https://code.google.com/p/chromium/issues/detail?id=314469
CONFIRM https://src.chromium.org/viewvc/blink?revision=161598&view=revision
CONFIRM http://support.apple.com/kb/HT6145
CONFIRM http://support.apple.com/kb/HT6162
CONFIRM http://support.apple.com/kb/HT6163
DEBIAN DSA-2811
SUSE openSUSE-SU-2013:1927
SUSE openSUSE-SU-2013:1933
SUSE openSUSE-SU-2014:0065
SECTRACK 1029442
SECUNIA 56217